CVE-2026-42167PoC(proftpd / proftpd)

CRITICALCVSS 8.1 · HIGH

Exploitation observed; activity peaked at 7 mentions and remains active

Immediate actions

  • Patch proftpd proftpd systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USER requests with an expansion such as %U, and the SQL backend allows commands (e.g., COPY TO PROGRAM).

8.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • proftpd

Threat summary

  • Active exploitation appears in 4 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 32 mentions across 16 observed days

What's happening

  • Active exploitation reported across 4 signals
  • Exploit tool or code specified in 10 signals
  • PoC mentioned or linked in 19 signals
  • Patch or workaround mentioned in 13 signals
  • Technical details provided in 26 signals
  • Disclosure: 7 classified signals
  • Peaked 13d ago at 7 mentions (2026-04-29); latest day: 1
  • 32 total mentions across 16 days

Affected systems

Vendors
Products
proftpd

Deep dive

Activity timeline32 mentions / 16d
02457Mentions · 2026-04-27: 1Mentions · 2026-04-28: 1Mentions · 2026-04-29: 7Mentions · 2026-04-30: 7Mentions · 2026-05-01: 2Mentions · 2026-05-02: 1Mentions · 2026-05-04: 2Mentions · 2026-05-07: 1Mentions · 2026-05-11: 1Mentions · 2026-07-17: 1Mentions · 2026-08-05: 1Mentions · 2026-08-14: 1Mentions · 2026-08-25: 3Mentions · 2026-09-01: 1Mentions · 2026-10-02: 1Mentions · 2026-10-03: 1PoC Mentioned / Linked · 2026-04-28: 1PoC Mentioned / Linked · 2026-04-29: 5PoC Mentioned / Linked · 2026-04-30: 5PoC Mentioned / Linked · 2026-05-01: 2PoC Mentioned / Linked · 2026-05-04: 2PoC Mentioned / Linked · 2026-07-17: 1PoC Mentioned / Linked · 2026-08-05: 1PoC Mentioned / Linked · 2026-08-25: 1PoC Mentioned / Linked · 2026-09-01: 1Exploit Tool / Code · 2026-04-28: 1Exploit Tool / Code · 2026-04-29: 4Exploit Tool / Code · 2026-04-30: 3Exploit Tool / Code · 2026-07-17: 1Exploit Tool / Code · 2026-08-05: 1Active Exploitation · 2026-04-29: 1Active Exploitation · 2026-04-30: 1Active Exploitation · 2026-05-04: 1Active Exploitation · 2026-07-17: 1Patch / Workaround · 2026-04-27: 1Patch / Workaround · 2026-04-29: 3Patch / Workaround · 2026-05-01: 1Patch / Workaround · 2026-05-02: 1Patch / Workaround · 2026-05-04: 1Patch / Workaround · 2026-05-07: 1Patch / Workaround · 2026-05-11: 1Patch / Workaround · 2026-08-05: 1Patch / Workaround · 2026-08-14: 1Patch / Workaround · 2026-08-25: 2Technical Details · 2026-04-27: 1Technical Details · 2026-04-28: 1Technical Details · 2026-04-29: 6Technical Details · 2026-04-30: 5Technical Details · 2026-05-01: 2Technical Details · 2026-05-02: 1Technical Details · 2026-05-04: 1Technical Details · 2026-05-07: 1Technical Details · 2026-05-11: 1Technical Details · 2026-07-17: 1Technical Details · 2026-08-05: 1Technical Details · 2026-08-14: 1Technical Details · 2026-08-25: 3Technical Details · 2026-09-01: 104-2704-2804-2904-3005-0105-0205-0405-0705-1107-1708-0508-1408-2509-0110-0210-03
Signal classification6 categories
PoC
826.7%
Disclosure
723.3%
Patch
620.0%
Exploit
413.3%
General
310.0%
Active Exploitation
26.7%
Referenced assets25 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-271
Patch1
2026-04-281
PoC1
2026-04-297
Disclosure2Exploit1Patch1PoC3
2026-04-307
Active Exploitation1Disclosure3Exploit1General1PoC1
2026-05-012
Disclosure1PoC1
2026-05-021
Patch1
2026-05-042
Active Exploitation1General1
2026-05-071
Disclosure1
2026-05-111
Patch1
2026-07-171
Exploit1
2026-08-051
PoC1
2026-08-141
Patch1
2026-08-253
General1Patch1PoC1
2026-09-011
Exploit1
Full discourse20 posts
  • LeftenantZero@LeftenantZero
    PoC

    CVE-2026-42167, a high severity vuln in ProFTPD I discovered, was just published today! Attackers can use it to bypass auth and even execute arbitrary code in some cases. Check out my write up for full technical details, including a working POC! https://zeropath.com/blog/proftpd-cve-2026-42167-auth-bypass-privesc-rce https://t.co/uFyjwlO7xs

    Post summary

    The author announces the newly discovered CVE-2026-42167 against ProFTPD, highlights its high severity, and provides a link to a write-up containing a working proof‑of‑concept that demonstrates auth bypass and possible RCE, but does not report active exploitation or a patch.

    5117246722127.1K
    267 followersView on X
  • !Manan@0xManan

    FTP `USER` alone. No password. SQLLog thinks your quote-wrapped name is “already escaped.” CVE-2026-42167 (CVSS 8.1) - ProFTPD `mod_sql` ≤ 1.3.9. Chain: `is_escaped_text()` skips escaping for `'…'` → `%U` in `SQLNamedQuery` becomes raw SQL on failed login (`SQLLog ERR_*`) → stacked `INSERT` plants uid 0 / `homedir=/` backdoor user → or PostgreSQL `COPY TO PROGRAM` = RCE on the DB host. Config gate: SQLLog interpolating attacker-controlled `%U` (common hosting pattern). Patch to 1.3.9a or kill mod_sql logging of pre-auth vars. PoC: https://github.com/ZeroPathAI/proftpd-CVE-2026-42167-poc Writeup: https://zeropath.com/blog/proftpd-cve-2026-42167-auth-bypass-privesc-rce #ProFTPD #SQLi #RCE #InfoSec ~160k ProFTPD on Shodan. If yours logs `%U` pre-auth, this is not theoretical.

    031191656.1K
    2.2K followersView on X
  • zauth@zauthinc
    Patch

    Caught a released-vs-master patch gap in ProFTPD's mod_sql.c (CVE-2026-42167, CVSS 8.1 High). The fix existed in master but never got backported to the 1.3.9 release branch, so anyone running the official release was still exposed. We flagged it, and the maintainer confirmed and shipped the backport within a day. First of many.

    Post summary

    The post reports a high‑severity bug in ProFTPD’s mod_sql.c that was patched quickly after being flagged. The maintainer backported the fix to the released 1.3.9 branch within a day.

    8332100167.7K
    7.2K followersView on X
  • Yusuf Can Çakır@Yusufcancakiir
    Exploit

    Found an open directory hosting a layered financial fraud operation across three simultaneous tracks: a Magecart-style card skimmer chain, a mass CVE exploitation framework, and a trojan distributed through Chinese streaming software packaging. All of it feeding the same PII collection pipeline. The skimmer track starts with FOFA. The actor runs automated queries targeting WooCommerce, Magento, and Stripe-integrated checkout pages, sorting results into structured target lists by category: builder_woo_checkout, stripe_woo_checkout, magento_checkout, checkout_cdn_js. Output lands in pii_consolidated.csv, with a second batch file visible alongside it. This has been running in passes. The skimmer component is a WooCommerce and Stripe-targeted Magecart payload. Injection engine supports page-level download, mitmproxy transparent proxy, and browser console delivery. C2 receiver runs on the same host. Target profile: Stripe Elements checkout pages, WooCommerce wc-ajax endpoints. The exploitation track runs in parallel. poc_scanner.py drives 300 concurrent probes against FOFA-sourced targets through a three-stage pipeline: liveness check, service fingerprinting, then PoC verification. CVEs being actively weaponized: CVE-2026-21858 — n8n unauthenticated RCE, CVSS 10.0 CVE-2026-6815 — Casdoor path traversal to RCE, CVSS 9.8 CVE-2026-32604 — Spinnaker shell injection, CVSS 10.0 CVE-2026-34486 — Tomcat Tribes auth bypass to RCE, CVSS 9.8 CVE-2026-25212 — Percona PMM RCE, CVSS 9.9 CVE-2026-35273 — PeopleSoft unauthenticated SSRF to RCE, CVSS 9.8 CVE-2026-23744 — MCPJam Inspector unauthenticated RCE, CVSS 9.8 CVE-2026-42167 — ProFTPD CVE-2026-6182 — SQL injection auth bypass CVE-2025-24587, CVE-2025-4396 A separate WordPress track runs alongside: mass SQL injection via wp_sqli_mass.py, aggressive dump via wp_aggressive_dump.py, PhpMyAdmin brute-force against the same pool. The trojan track is socially engineered. 直播助手化.v2.exe presents as a legitimate Chinese streaming helper application. VMProtect 3.2–3.5 wrapping. 29/70 on VirusTotal at time of analysis. Family: flystudio, chinad, dlii. It ships with HPSocket4C.dll, pb.dll, pb64.dll, and gzip.dll as side-loaded components. The infection surface is Chinese-speaking streaming users who would recognize the product name as familiar tooling. C2 routes through v2ray. Two license spoofing servers complete the toolkit. bypass_server.py impersonates http://premium.dotbypasser.workers.dev, handling RSA-OAEP encrypted license exchange and returning forged validation responses with 10-year expiry timestamps. fake_auth_server.py covers a separate streaming platform, impersonating http://api.vmks.cn and related domains, returning fake authorization tokens. Both appear to serve tooling distribution rather than direct victim infrastructure. One additional finding on the C2 host: evidence of AI-assisted offensive operations. A DeepSeek API configuration points to http://api.deepseek.com through an Anthropic-compatible interface, and a structured offensive security framework containing 70+ purpose-built skill modules for vulnerability classes including SQLi, XSS, SSRF, RCE, IDOR, OAuth, SAML, cloud misconfiguration, Kubernetes, CI/CD, M365/Entra, VMware vCenter, and supply chain recon. The actor is running systematized, AI-assisted attack methodology. This pattern is increasingly documented across financially motivated operations. OPSEC failure on an otherwise capable operator. filter_cn.py is on the box and actively used. It strips Chinese IP ranges from FOFA output sets before exploitation runs begin. The actor is deliberately skipping domestic targets, a consistent behavioral marker across Chinese financially motivated operations. Additionally, the FOFA API credential is hardcoded in cleartext across the client scripts. Easy attribution anchor.

    Post summary

    The post details an active threat actor with ready-to-use scripts that weaponize multiple CVEs, perform mass exploitation, and exfiltrate data, underscoring the operational readiness and scale of the operation.

    215054404.8K
    1.6K followersView on X
  • Nicolas Krassas@Dinosn
    PoC

    Independent reproduction, code-level root-cause analysis, and realistic-exposure write-up for CVE-2026-42167 (ProFTPD mod_sql is_escaped_text() bypass). https://github.com/dinosn/proftpd-CVE-2026-42167-analysis

    Post summary

    Shares a GitHub analysis demonstrating a bypass in ProFTPD's mod_sql module (CVE‑2026‑42167), including code‑level reproduction but no active exploitation or patch info.

    0301271.5K
    158.1K followersView on X
  • Clandestine@akaclandestine
    PoC

    GitHub - ZeroPathAI/proftpd-CVE-2026-42167-poc: POCs to demonstrate CVE-2026-42167 in ProFTPD · GitHub https://github.com/ZeroPathAI/proftpd-CVE-2026-42167-poc

    Post summary

    A GitHub repository hosts proof‑of‑concept code demonstrating CVE‑2026‑42167 against ProFTPD; it does not provide evidence of active exploitation, patches, or a false‑positive claim.

    010941.2K
    62.1K followersView on X
  • Ryx@PadhiyarRushi

    ProFTPD mod_sql still has a pre-auth backdoor path if SQLLog interpolates %U inside quotes!!! CVE-2026-42167 is_escaped_text() in contrib/mod_sql.c misses the break-out. Pre-auth %U injects a uid 0 user into the auth table. PostgreSQL COPY TO PROGRAM is the RCE path, and only if that DB role is superuser. Fixed in 1.3.9a / 1.3.10rc1. Config-dependent. Not a default install. https://github.com/ZeroPathAI/proftpd-CVE-2026-42167-poc #Cybersecurity #AI #AISecurity #MCP #Claude #GPT #Infosec #Trending #NetworkSecurity #SQLi #RCE

    03064311
    954 followersView on X
  • Open Source Security mailing list@oss_security
    Patch

    CVE-2026-42167: ProFTPd: SQL injection https://www.openwall.com/lists/oss-security/2026/05/01/4 Depending on configuration, the flaw can be exploited before authentication and may lead to authentication bypass, privilege escalation, or remote code execution. Fixed in 1.3.9a.

    Post summary

    CVE-2026-42167 is an SQL injection in ProFTPd that can lead to authentication bypass and remote code execution, and the issue is fixed in version 1.3.9a.

    02172908
    4.7K followersView on X
  • dbugs@ptdbugs
    PoC

    CVE-2026-42167: pre-auth SQL injection in ProFTPD An SQL injection vulnerability was discovered in the "mod_sql" module of the ProFTPD FTP server. It is tracked as CVE-2026-42167 -> (https://dbugs.ptsecurity.com/vulnerability/CVE-2026-42167) and has a CVSS score of 8.1. The issue was caused by the "is_escaped_text()" function. It considered a string safely escaped if it: • started with "'" • ended with "'" • contained no other single quotes This heuristic was originally added for the trusted internal call "mod_quotatab_sql", to avoid double escaping. However, "mod_sql" applied it to all data, including values received from the FTP client. As a result, the server accepted user input as part of an SQL command such as "USER '<SQL payload>'". The value was passed to "SQLNamedQuery", passed the check as “already escaped,” and was inserted into the query without calling "sql_escapestring". The attack worked even when authentication failed, if the server logged "USER" commands through "SQLLog ERR_*". When PostgreSQL was used, an attacker could leverage stacked queries to add a new FTP account to the SQL table with "UID 0" and the home directory "/", and then authenticate as that account. If the database allowed "COPY TO PROGRAM" or a similar mechanism, the SQL injection could lead directly to command execution. In the fix, the developers separated data sources: client-supplied variables are now forcibly escaped before entering the shared resolver. The flaw had existed since November 2020, and the patch was introduced in commit "e6f72848". Article: https://nefariousplan.com/posts/proftpd-mod-sql-the-heuristic-was-for-one-caller PoC: https://github.com/dinosn/proftpd-CVE-2026-42167-analysis #dbugs_attacks

    Post summary

    The post discloses a pre‑auth SQL injection in ProFTPD’s mod_sql module, provides a PoC link, details the technical exploitation method, and notes the available patch.

    00072518
    3.6K followersView on X
  • Hackviser@hackviserr
    PoC

    Ready to bypass authentication and execute remote commands on a ProFTPD server? ⚡️🚨 Just added to Hackviser Labs: ProFTPD Authentication Bypass &amp; Remote Code Execution (CVE-2026-42167) 🔥 Join Hackviser to start the lab now 🚀 https://t.co/IObTCtcMd7

    Post summary

    A new ProFTPD authentication bypass and remote code execution vulnerability (CVE‑2026‑42167) has been added to Hackviser Labs, likely including a proof‑of‑concept exploit for testing purposes.

    01052366
    4.4K followersView on X
  • Rıdvan Yağlı@ridvanyagli
    PoC

    🔴 ProFTPD'de CVSS 8.1 seviyesinde kritik bir açık: CVE-2026-42167 ProFTPD'nin mod_sql modülündeki SQL Injection açığı, uygun yapılandırmalarda kimlik doğrulama gerektirmeden istismar edilebiliyor. Açık; kimlik doğrulama atlatma, yetki yükseltme ve bazı PostgreSQL yapılandırmalarında uzaktan kod çalıştırmaya (RCE) kadar ilerleyebiliyor. Üstelik açık için çalışan PoC'ler de yayınlandı. Etkilenen sürümler için ProFTPD'nin 1.3.9a ve üzeri sürüme güncellenmesi öneriliyor.

    Post summary

    CVE-2026-42167 is a critical SQL injection flaw in ProFTPD's mod_sql that can lead to authentication bypass, privilege escalation, and remote code execution; PoCs have been released and the vendor recommends updating to 1.3.9a or later.

    00061671
    2.4K followersView on X
  • Mr. OS@ksg93rd
    Exploit

    #exploit #AppSec 1⃣. CVE-2026-42167: RCE, authentication bypass, and privilege escalation in ProFTPD <=1.3.9 https://github.com/ZeroPathAI/proftpd-CVE-2026-42167-poc 2⃣. CVE-2026-41940: Critical vulnerability in cPanel & WHM allowing session hijacking and authentication bypass via CRLF injection https://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/ 3⃣. CVE-2026-40478: Thymeleaf server-side template injection vulnerability https://snyk.io/blog/thymeleaf-injection/ 4⃣. CVE-2026-3854: RCE in GitHub*com/GitHub Enterprise Server https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854 5⃣. CVE-2026-20079: Critical Cisco FMC Zero-Day https://github.com/0xBlackash/CVE-2026-20079

    Post summary

    The tweet lists five CVEs, each with an explicit proof‑of‑concept or functional exploit link, but does not reference active wild exploitation or vendor patches.

    01032886
    3.3K followersView on X
  • 보안프로젝트@ngnicky
    Disclosure

    최근 ZeroPath Research를 통해 ProFTPD의 특정 모듈(mod_sql)에서 발생하는 심각한 보안 취약점(CVE-2026-42167)이 공개되었습니다. 이 취약점은 인증 우회는 물론, 특정 조건에서 서버의 제어권을 완전히 탈취할 수 있는 위험성을 내포하고 있습니다. https://zeropath.com/blog/proftpd-cve-2026-42167-auth-bypass-privesc-rce https://t.co/TNDSvHGs7Q

    Post summary

    ZeroPath Research has disclosed a critical authentication bypass and privilege escalation flaw in ProFTPD’s mod_sql module (CVE‑2026‑42167), with a link to detailed information, but no active exploitation or patch information is provided.

    01032224
    6.8K followersView on X
  • Frank R.@FrankReich9
    Disclosure

    Linux-Administratoren werden wohl (k)ein langes Wochenende haben: proFTPD (CVE-2026-42167), cPanel/WHM (CVE-2026-41940) und insb. CopyFail (CVE-2026-31431). Für CopyFail existieren bereits Go- und C-Forks. https://t.co/MzUsl0x0hu

    Post summary

    The tweet announces three CVEs affecting Linux systems and notes that code forks already exist for CopyFail, but it does not report active exploitation or patches.

    011301.9K
    1.2K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-42167 - high 🚨 ProFTPD mod_sql - Preauth User Backdoor &gt; ProFTPD mod_sql before 1.3.10rc1 contains a remote code execution caused by unsafe us... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-42167 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet announces the discovery of CVE‑2026‑42167, a pre‑authentication RCE backdoor in ProFTPD mod_sql before version 1.3.10rc1, and links to a resource with further details.

    00022208
    973 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 HIGH - ProFTPD mod_sql Unauth RCE (CVE-2026-42167) A vulnerability in mod_sql allows unauthenticated RCE via malicious SQL logging expansions. Attackers can use crafted usernames to break SQL strings and execute OS-level commands through the database backend. 👉 Affected: < 1.3.10rc1 | Upgrade to v1.3.10rc1

    Post summary

    The post announces an unauthenticated RCE in ProFTPD mod_sql (CVE‑2026‑42167) and advises upgrading to v1.3.10rc1 to remediate the issue.

    0004085
    237 followersView on X
  • ZeroPath@ZeroPathAI
    PoC

    ZeroPath discovered CVE-2026-42167 in ProFTPd, one of the internet's most popular FTP daemons. The flaw allows for auth bypass and even pre-auth RCE in some configurations. Update to 1.3.9a now! https://zeropath.com/blog/proftpd-cve-2026-42167-auth-bypass-privesc-rce Take a look at the blog for technical details and a working POC.

    Post summary

    ZeroPath announced CVE-2026-42167 in ProFTPd, revealing an authentication bypass that can lead to pre‑auth remote code execution, and supplied a working PoC plus a patch recommendation to upgrade to version 1.3.9a.

    00021173
    231 followersView on X
  • Constantin Milos ♏@Tinolle infosec.exchange@Tinolle1955
    Disclosure

    CVE-2026-42167 Allows Auth Bypass And RCE In ProFTPD https://zeropath.com/blog/proftpd-cve-2026-42167-auth-bypass-privesc-rce

    Post summary

    CVE‑2026‑42167 is a newly disclosed flaw in ProFTPD that permits authentication bypass and remote code execution; the announcement provides technical details but no PoC, patch, or evidence of active exploitation.

    01010164
    4.6K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    ProFTPD の脆弱性 CVE-2026-42167 が FIX:SQL インジェクションによる RCE https://iototsecnews.jp/2026/04/30/proftpd-sql-injection-flaw-opens-door-to-remote-code-execution-attack/ ProFTPD の脆弱性 CVE-2026-42167 は、 mod_sql モジュールにおけるデータの取り扱い方に起因するものです。本来であれば、外部からの入力は厳重にチェックされるべきですが、このケースでは攻撃者が操作できるユーザー名などの情報が、すでに安全なものとして誤って処理されてしまいました。 その結果、 SQL クエリの構造が壊され、第三者がデータベースを自由に操作できてしまう状態が生じています。特に PostgreSQL を利用している環境では、 OS のコマンド実行にまで被害が広がる恐れがあるため、非常に注意が必要です。ご利用のチームは、ご注意ください。 #CVE202642167 #ProFTPD #Vulnerability

    Post summary

    The post announces the discovery of a CVE‑2026‑42167 vulnerability in ProFTPD’s mod_sql module, explains its technical aspects (SQL injection leading to RCE), and indicates that a fix is available.

    01000107
    487 followersView on X
  • CCB Alert@CCBalert
    Active Exploitation

    Warning: SQL injection in #ProFTPD mod_sql actively exploited! #CVE-2026-42167 CVSS: 8.1. Pre-auth RCE &amp; auth bypass via logging % expansions. 162k+ internet-facing instances at risk (https://zeropath.com/blog/proftpd-cve-2026-42167-auth-bypass-privesc-rce). Upgrade to ≥1.3.9a NOW! #Patch #Patch #Patch http://www.proftpd.org/docs/RELEASE_NOTES-1.3.10rc1

    Post summary

    The post warns of a high‑severity SQL injection vulnerability in ProFTPD that is being exploited in the wild; it urges immediate patching to version 1.3.9a and directs readers to detailed technical information and a patch reference.

    01000188
    7.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appproftpdproftpd---

Explore more